Skip to content

TruStage cyberattack and systems outage

Summary

TruStage logo

TruStage’s July 11 cyberattack affected its primary technology environment and backup infrastructure, forcing a cloud rebuild. As of Sept. 21, claims, policy servicing and disbursement functions remained partially available while restoration continued. TruStage also said it was developing grants for members who experienced incident-related hardship; data access, ransomware and attribution remained unresolved.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted location

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Malware

    Malicious software other than ransomware used to compromise or disrupt systems.

  • Insider threat

    Malicious or negligent actions by an authorized insider resulting in cyber impact.

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

  • Backup compromise

    Backup data or backup systems were accessed, encrypted, deleted, altered, disabled, or otherwise compromised.

Operational impacts

  • Complete service outage

    A primary service, system, platform, or operational capability became entirely unavailable.

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Application unavailable

    A specific application or software platform became unavailable or unusable.

  • Payment processing disruption

    The organization could not process, receive, issue, reconcile, or record payments normally.

  • Transaction processing disruption

    Business, financial, customer, administrative, or operational transactions could not be completed normally.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Event or activity cancellation

    Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

  • Backlog created

    The disruption caused an accumulation of unprocessed requests, cases, orders, records, appointments, or other work.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

  • Downstream organization impact

    The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that malicious cyber activity affected TruStage’s technology environment and caused a prolonged systems outage. TruStage’s outage hub describes a broad cybersecurity attack identified July 11 and says the company had to rebuild parts of its infrastructure before safely returning systems to service. July 11 is the earliest supported detection date, not a confirmed intrusion-start date.

TruStage’s credit-union guidance says the investigation indicated that a workforce member may have inadvertently downloaded a malicious file while attempting to install a legitimate tool. DysruptionHub assesses malware and negligent insider action as probable mechanisms with medium confidence. TruStage has not identified the file, delivery route, malware family, affected hosts or subsequent attacker activity.

Operational significance

The incident disrupted customer and partner-facing insurance, claims, payment, transaction and account-access functions. TruStage used temporary processes for guaranteed asset protection claims, debt-protection benefits and mechanical-repair coverage, while credit unions were told to retain some monthly files until receipt and processing capabilities returned. The company acknowledged delays, processing exceptions and a claims backlog as systems came back online.

First Alert 4 reported that a delayed life-insurance payment postponed a Collinsville, Illinois, family’s funeral after Mary Farmer died Aug. 8. Her brother advanced the funeral cost before TruStage told the station Aug. 26 that it had resolved the claim. Missouri funeral directors also reported other funeral homes serving families while TruStage payments were pending. One other funeral-home delay began before the attack, so the incident does not explain its entire duration.

CU Today reported Sept. 11 that TruStage was developing a grant fund for credit union members who experienced incident-related financial hardship. CEO Terrance Williams acknowledged continuing service failures and said the investigation into possible member-data compromise would take at least two more months. The grant announcement documents continuing consequences but does not establish data compromise.

An Aug. 27 partner update reported by CU Today said the attack affected TruStage’s primary operating environment and elements of the backup infrastructure it expected to use for recovery. TruStage developed an alternate strategy that required rebuilding and restoring significant portions of its technology environment in the cloud. This establishes that backup systems were compromised as a recovery resource, but it does not establish that backup data was encrypted, deleted or permanently lost.

TruStage also canceled Discovery 2026, its virtual credit-union conference scheduled for Aug. 27, to focus on recovery and support for customers, partners and employees.

Current status

The incident remained active Sept. 21. TruStage’s official outage hub said some services remained unavailable and continued to list claims, policy servicing and disbursements as partially available while recovery proceeded. The company had not announced full restoration.

Disclosure posture

TruStage directly confirmed the cyberattack, network shutdown, infrastructure rebuilding and phased recovery. Its statements support containment and continuing restoration, but the public record does not explain precisely how the attack affected the backup environment or why the available backup layers could not support the planned recovery path.

The company said its investigation into whether member, employee or other information was compromised remained underway and could take another two to three months. The reviewed evidence does not establish encryption, a ransom demand, extortion, data publication or a responsible actor.

Confidence and uncertainty

Cyber and operational-impact confidence are high because TruStage directly confirmed the attack and continued to document service effects. The CEO’s statement supports high confidence that elements of backup infrastructure were affected and that the recovery plan shifted to a substantial cloud rebuild. Confidence in malware and negligent insider action remains medium because the malicious-file finding is preliminary.

Availability impact is established for production services, data access and backup systems. Confidentiality and integrity effects remain unresolved because TruStage has not determined publicly whether information was accessed, acquired, altered or removed. Ransomware, extortion and threat-actor attribution also remain unresolved.

Analytic gaps

The public record does not establish the intrusion start, dwell time, delivery method, file or legitimate tool involved, malware family, affected hosts, persistence, lateral movement, privilege escalation or command-and-control activity. It does not identify which backup systems were affected, whether backup copies remained intact, how much recovery data was unavailable or how the attacker reached the backup environment.

The total number of affected customers, policies, claims, transactions, credit unions, funeral homes or other partners remains unknown. The final restoration date, size and disposition of deferred work, data-access findings and any notification obligations also remain unresolved.

Organizations involved

Impacted location

Sources

TruStage cyber incident disrupts credit union claims

We reported that TruStage shut down its network after identifying a cybersecurity incident and that some credit-union-linked claims were affected. TruStage had not disclosed the compromise method, data impact, restoration date, ransomware, a ransom demand or a threat actor.

TruStage Shuts Down Network After Detecting Cybersecurity Incident

CU Today reproduced TruStage’s stakeholder message stating that the company identified a cybersecurity incident, proactively shut down its network, activated incident-response and recovery efforts, and engaged external specialists for containment, remediation, and recovery.

TruStage Says Employee Likely Triggered Cyber Incident by Downloading Malicious File

Credit Union Times reported that TruStage President and CEO Terrance Williams told credit-union customers the investigation indicated a workforce member may have inadvertently downloaded a malicious file while attempting to install a legitimate tool. The report characterized this as the first public indication of how the incident may have begun.

Member notice | TruStage experiences a disruption in service

Service 1st said TruStage identified the incident July 11, proactively shut down access to its network and systems, and was working to restore normal operations. Service 1st said its own systems were unaffected and it had not been informed that member information was compromised.

TruStage service disruption

TruStage’s July 24 consumer update said investigation remained active and customers could have difficulty accessing account information, completing transactions or submitting requests online. Active coverage and grace-period policies would retain their status until regular payment processing resumed, and claims would be processed and paid once systems were able.

Cybersecurity incident update for individual customers

TruStage’s July 31 guidance said restoration remained underway; customers and representatives still faced account-access, transaction, request and payment limitations; claims would be paid as systems permitted; retirement balances were unaffected but online access was still being restored; and any personal-information access remained undetermined.

Cybersecurity incident update for credit unions

On Aug. 30, TruStage still listed claims submission, processing and payout; policy and contract servicing; and disbursements as partially available overall. BenefitsForYou remained unavailable, account access was limited, and multiple claims, payment and partner processes still depended on temporary channels.

TruStage confirms clean, isolated technology environment

TruStage said it had established a clean, isolated environment for phased restoration. Some contact centers, claims payments, billing and retirement withdrawals or loans had resumed, but longer handling times, limited capabilities and a claims backlog remained. The company said its data investigation could take another two to three months.

Some families have faced funeral delays after cyberattack on TruStage insurance

First Alert 4 reported that a delayed TruStage life-insurance payment postponed a Collinsville family’s funeral after an Aug. 8 death. TruStage said it resolved that claim and another claim described by the station after the inquiry. Missouri funeral directors also reported other funeral homes serving families while TruStage payments were pending. One woman’s reported stay at a funeral home began in June, before the July 11 attack, so the incident does not explain that entire delay.

TruStage Says Cyberattack Hit Backup Systems, Names Interim CIO

CU Today reported that TruStage President and CEO Terrance Williams said the attack affected the company’s primary operating environment and elements of backup infrastructure intended for recovery. TruStage developed an alternate recovery strategy and rebuilt significant portions of its technology environment in the cloud. The company also named Kirsten Garen interim CIO, retained Pat Lawicki as a consultant and added PwC to the recovery effort. The report does not say backup data was encrypted, deleted or permanently lost.

TruStage Plans Grants For Members Hurt By Cyberattack As CEO Says Company ‘Fell Down’

CU Today reported that TruStage was developing a grant fund for credit union members who experienced incident-related financial hardship and that its investigation into possible member-data compromise would take at least two more months.

TruStage is Temporarily Unavailable

The credit union said vendor partner TruStage was experiencing systems outages and warned members of temporary inconvenience when submitting claims for GAP insurance, mechanical repair coverage, or payment protection products.

TruStage systems outage notice

TruStage’s homepage still displayed a systems-down notice August 10 and described the event as a cybersecurity attack while teams worked on recovery and business-resiliency plans.

Discovery 2026 canceled

TruStage canceled Discovery 2026 because of the cybersecurity attack affecting certain systems and services. The company said the decision allowed it to focus on recovery and supporting customers, partners and employees, and that conference content would be moved to a later thought-leadership series.

Claims restoration status

On Aug. 30, TruStage’s dashboard showed annuity claim payouts unavailable and most other claim categories partially available. It expected most pre-outage life and accidental-death claims to be paid by the end of the following week, with some claims still needing documentation, and said review of guaranteed asset protection claims submitted after July 11 had begun.

Disbursements restoration status

On Aug. 30, TruStage listed life-policy one-time disbursements and surrenders as unavailable, retirement and executive-benefit disbursements as partially available, and annuity disbursements as available. The product-level variation showed significant recovery but not full restoration.

Policy servicing restoration status

On Aug. 30, TruStage listed all Payment Guard servicing as unavailable, Bond Suite servicing as largely unavailable, and life, accidental-death, retirement and several other product functions as partially available. Annuity and third-party-supported products had broader restoration, but the dashboard did not show complete servicing recovery across the business.

Information on TruStage's systems outage

TruStage’s Sept. 21 outage hub said restoration continued after the July 11 attack. Claims, policy servicing and disbursement functions remained partially available, and some services remained unavailable.

See something that needs correction?

Signed-in members can report an error, update, or missing source.